HTTP Status Codes

[ STATUS CODES ]
34
Maghanap ayon sa numero, pangalan o gamit.
Mali ng kliyente14
Nabigo ang server5
Kabuuan34
100ContinueRFC 9110 §15.2.1

The request headers are fine; send the body.

Almost never set by hand. A client sends Expect: 100-continue before a large body so it can be rejected before uploading.

101Switching ProtocolsRFC 9110 §15.2.2

The connection is changing protocol, usually to WebSocket.

Emitted by the server during a WebSocket handshake. Not something an application returns.

103Early HintsRFC 8297

Preliminary headers while the real response is prepared.

To send Link headers so the browser can preload assets before the page itself is ready.

200OKRFC 9110 §15.3.1

The request succeeded and the body carries the result.

The default for a successful GET, or a PUT or POST that returns content.

201CreatedRFC 9110 §15.3.2

The request succeeded and a new resource now exists.

A POST or PUT that created something. Send a Location header pointing at it — that is the part usually forgotten.

Madalas mapagkamalan sa 200 OK · 202 Accepted

202AcceptedRFC 9110 §15.3.3

The request was accepted but has not been carried out yet.

Queued work. Use it when you cannot promise the result, and give the caller somewhere to check progress.

Madalas mapagkamalan sa 201 Created · 200 OK

204No ContentRFC 9110 §15.3.5

Succeeded, and there is deliberately no body.

A DELETE that worked, or a PUT with nothing to return. A 204 with a body is a contradiction and some clients will drop it.

Madalas mapagkamalan sa 200 OK · 205 Reset Content

205Reset ContentRFC 9110 §15.3.6

Succeeded, and the client should clear the form it sent.

Rare, and genuinely different from 204: 204 says "nothing to show", 205 says "nothing to show AND reset your input". Also carries no body.

Madalas mapagkamalan sa 204 No Content

206Partial ContentRFC 9110 §15.3.7

Part of the resource, in response to a Range request.

Video seeking and resumable downloads. Must echo Content-Range.

301Moved PermanentlyRFC 9110 §15.4.2

The resource has a new URL, for good.

A permanent move. Crawlers transfer ranking signals to the new URL. **Cached aggressively and hard to undo** — be sure before sending one.

Madalas mapagkamalan sa 302 Found · 308 Permanent Redirect

302FoundRFC 9110 §15.4.3

The resource is temporarily elsewhere.

A temporary move. Historically it let clients change POST to GET, which is why 307 exists.

Madalas mapagkamalan sa 301 Moved Permanently · 307 Temporary Redirect

303See OtherRFC 9110 §15.4.4

Look at this other URL, with a GET.

After a successful POST, to stop a refresh resubmitting the form. The POST-redirect-GET pattern.

Madalas mapagkamalan sa 302 Found · 307 Temporary Redirect

304Not ModifiedRFC 9110 §15.4.5

Your cached copy is still good.

In reply to a conditional request carrying If-None-Match or If-Modified-Since. Carries no body by design.

307Temporary RedirectRFC 9110 §15.4.8

Temporarily elsewhere, and keep the method.

Like 302 but the method and body must be preserved — a POST stays a POST. Use it when that matters.

Madalas mapagkamalan sa 302 Found · 308 Permanent Redirect

308Permanent RedirectRFC 9110 §15.4.9

Permanently elsewhere, and keep the method.

Like 301 but the method is preserved. The right choice for a permanently moved API endpoint.

Madalas mapagkamalan sa 301 Moved Permanently · 307 Temporary Redirect

400Bad RequestRFC 9110 §15.5.1

The request is malformed and the server will not process it.

Syntax errors — unparseable JSON, a missing required field. Not for a request that is well-formed but refused.

Madalas mapagkamalan sa 422 Unprocessable Content · 404 Not Found

401UnauthorizedRFC 9110 §15.5.2

You are not authenticated. The name is wrong — it means unauthenticated.

No credentials, or bad ones. Signing in could fix it. Must carry a WWW-Authenticate header.

Madalas mapagkamalan sa 403 Forbidden

403ForbiddenRFC 9110 §15.5.4

You are authenticated and still not allowed.

Signing in again will not help. **The distinction from 401 is the single most muddled pair in HTTP**: 401 is "who are you?", 403 is "I know who you are, and no".

Madalas mapagkamalan sa 401 Unauthorized · 404 Not Found

404Not FoundRFC 9110 §15.5.5

No resource at this URL.

Also the right answer when you do not wish to confirm a resource exists to someone with no right to it — better than 403 there, because a 403 confirms it.

Madalas mapagkamalan sa 403 Forbidden · 410 Gone

405Method Not AllowedRFC 9110 §15.5.6

The URL exists; that verb does not apply to it.

A POST to a read-only endpoint. Must list the permitted verbs in an Allow header.

Madalas mapagkamalan sa 404 Not Found · 501 Not Implemented

409ConflictRFC 9110 §15.5.10

The request clashes with the current state.

An edit against a version that has since moved, or a duplicate unique value. Say what conflicted.

Madalas mapagkamalan sa 422 Unprocessable Content · 412 Precondition Failed

410GoneRFC 9110 §15.5.11

It was here and has been deliberately removed.

Stronger than 404: it tells a crawler to drop the URL rather than keep retrying. Only when you know it is permanent.

Madalas mapagkamalan sa 404 Not Found

412Precondition FailedRFC 9110 §15.5.13

A condition you attached did not hold.

The other half of optimistic concurrency, with If-Match. Stops a blind overwrite.

Madalas mapagkamalan sa 409 Conflict · 428 Precondition Required

413Content Too LargeRFC 9110 §15.5.14

The body is bigger than the server will take.

Upload limits. Formerly "Payload Too Large".

415Unsupported Media TypeRFC 9110 §15.5.16

The Content-Type is not one this endpoint accepts.

A form posted to a JSON-only endpoint. About the format, never about the values.

Madalas mapagkamalan sa 400 Bad Request · 422 Unprocessable Content

422Unprocessable ContentRFC 9110 §15.5.21

Well-formed, understood, and semantically wrong.

Validation failures — a date in the past where a future one is required. **This is the code most APIs should use where they send 400.**

Madalas mapagkamalan sa 400 Bad Request · 409 Conflict

428Precondition RequiredRFC 6585 §3

The server insists the request be conditional.

Forces a client to send If-Match, so concurrent edits cannot silently overwrite each other.

429Too Many RequestsRFC 6585 §4

You are being rate limited.

Send Retry-After. A 429 with no indication of when to try again leaves a client guessing or hammering.

451Unavailable For Legal ReasonsRFC 7725

Blocked for legal reasons.

Court orders and statutory blocks. The number is a Fahrenheit 451 reference and that is deliberate.

500Internal Server ErrorRFC 9110 §15.6.1

Something broke and the server cannot be more specific.

The catch-all for an unhandled exception. Never leak the stack trace to the caller.

Madalas mapagkamalan sa 502 Bad Gateway · 503 Service Unavailable

501Not ImplementedRFC 9110 §15.6.2

The server does not support the method at all.

For a verb the server does not implement anywhere. Not for one that merely does not apply here — that is 405.

Madalas mapagkamalan sa 405 Method Not Allowed

502Bad GatewayRFC 9110 §15.6.3

A proxy got an invalid response from upstream.

The upstream answered with rubbish, or died mid-response. Your application is probably the upstream.

Madalas mapagkamalan sa 503 Service Unavailable · 504 Gateway Timeout

503Service UnavailableRFC 9110 §15.6.4

Temporarily unable to handle the request.

Maintenance or overload. Send Retry-After. **Use this rather than 500 during a deploy** — it tells a crawler to come back rather than to drop the page.

Madalas mapagkamalan sa 500 Internal Server Error · 502 Bad Gateway

504Gateway TimeoutRFC 9110 §15.6.5

A proxy gave up waiting for upstream.

The upstream never answered. 502 means a bad answer; 504 means no answer at all.

Madalas mapagkamalan sa 502 Bad Gateway · 503 Service Unavailable

[ ANO ITO ]

Hindi ang pangalan ang mahirap. Alam ng lahat na "Not Found" ang 404. Ang magkapares na madaling magkamali ang kumakain ng oras.

401 laban sa 403 ang pinakamalabo sa HTTP, at kasalanan ito ng pangalan: ang 401 ay nagsasabing "Unauthorized" pero ang ibig sabihin ay hindi pa nakikilala. Ang 401 ay "sino ka?"; ang 403 ay "kilala kita, at hindi puwede".

Ang 400 laban sa 422 ay isa pa. Ang 400 ay para sa hindi mabasang request; ang 422 ay para sa request na tama ang anyo at mali ang laman. Karamihan sa API ay nagpapadala ng 400 sa dalawa, at karamihan doon ay 422 talaga.

Kaya bawat entry dito ay may kailan gagamitin, hindi lang kahulugan — at pinapangalanan ang kapares na madaling mapagkamalan.

[ MGA TANONG ]

Ano ang pagkakaiba ng 401 at 403?

Ang 401 ay nangangahulugang hindi alam ng server kung sino ka — walang kredensiyal, o mali — at puwedeng maayos ito ng pag-sign in. Ang 403 ay nangangahulugang alam na alam niya kung sino ka at hindi ka pa rin puwede. Ang pangalan ng 401 ang problema: sinasabi nitong “Unauthorized” at ang ibig sabihin ay hindi napatunayan. Kailangan ding may dalang WWW-Authenticate header ang 401 na nagsasabi kung paano magpapatunay, at iyon ang bahaging madalas iwanan.

404 ba o 403 ang ibabalik ko para sa bagay na hindi dapat makita ng user?

Kadalasan ay mas magandang sagot ang 404. Kinukumpirma ng 403 na umiiral ang resource, at sinasabi niyon sa taong walang karapatan dito na nakahanap siya ng tunay na URL — ganoon inililista ng umaatake kung ano ang sulit atakihin. Walang ibinibigay ang 404. Ganoon din ang ginagawa ng site na ito para sa naka-save na datos ng ibang miyembro.

Kailan ko gagamitin ang 400 at kailan ang 422?

Ang 400 ay para sa request na hindi mabasa ng server — sirang JSON, kulang na kailangang patlang, ganap na maling hugis. Ang 422 ay para sa request na maayos ang anyo at mali ang kahulugan, tulad ng petsang nakaraan kung saan kailangan ng hinaharap. Karamihan sa API ay nagpapadala ng 400 sa dalawa, at karamihan sa mga kasong iyon ay 422 talaga.

Anong redirect ang dapat kong gamitin?

Dalawang tanong: permanente ba ito, at kailangan bang makaligtas ang method? Ang 301 ay permanente at sa kasaysayan ay pinapayagan ang kliyenteng gawing GET ang POST. Ang 308 ay permanente at pinapanatili ang method. Ang 302 ay pansamantala na may parehong kalabuan sa method; ang 307 ay pansamantala at pinapanatili ito. Para sa API endpoint na lumipat ay halos laging 308 ang gusto mo. Mag-ingat sa 301 — mabigat itong ina-cache at mahirap bawiin.

Ano ang pagkakaiba ng 502 at 504?

Parehong galing sa bagay na nakaupo sa harap ng aplikasyon mo. Ang 502 ay nangangahulugang sumagot ang upstream ng wala sa lugar, o namatay sa gitna ng pagsagot. Ang 504 ay nangangahulugang hindi kailanman sumagot ang upstream bago sumuko ang proxy. Kung inaayos mo ang sarili mong serbisyo sa likod ng proxy, ang 502 ay kadalasang tumuturo sa pagbagsak at ang 504 sa bagay na mabagal.

Ano ang dapat ibalik ng site habang nagde-deploy?

503 Service Unavailable, kasama ang Retry-After header. Sinasabi nito sa crawler na pansamantalang wala ang pahina at bumalik muli, samantalang ang 500 ay nagpapahiwatig na may sira at ang 404 ay nagpapahiwatig na wala na ang pahina. Ang maling pagbabalik sa loob ng ilang minuto ng pagmamantini ay puwedeng magpalabas ng pahina sa index.

Totoo ba ang 418 I’m a teapot?

Tunay itong nakarehistrong code mula sa espesipikasyong biro noong Abril 1998, at sinasadyang wala ito sa listahang ito. Walang silbi ito sa tunay na API, at ang pagsama nito katabi ng mga code na pinagpipilian ng mga tao ay nagdaragdag ng ingay sa isang sanggunian.

[ ANG KOMPUTASYON ]
Ang limang klase
1xxnatanggap, may susunod pa
2xxtagumpay
3xxmay dapat pang gawin
4xxmali ang request
5xxnabigo ang server

Ang 4xx at 5xx ang tunay na paghahati: sasabihin ng 4xx na baguhin ang request, at sasabihin ng 5xx na tama ang request at ang server ang may problema.

[ SA PANAHON NG DEPLOY ]

Magpadala ng 503 na may Retry-After. Sinasabi nito sa crawler na pansamantala lang at babalik ito. Ang 500 ay nagpapahiwatig ng sira; ang 404 ay nagpapahiwatig na wala na. Ang maling pagpili sa loob ng ilang minutong maintenance ay puwedeng magpatanggal ng pahina sa index.

[ SUSUNOD ]
73Hanapan ng MIME TypeThe other header you get wrong at 2am
46Gumawa ng JWTWhat is usually behind a 401
43JSON FormatterFor the body that came back with the error
60Hash GeneratorFor the ETag behind a 304
[ MAHALAGA ]

A reference, not a specification. Every code cites the RFC it comes from — read that where the exact wording matters. Walang ipinapadala sa mga server namin ang tina-type mo rito — sa browser mo tumatakbo nang buo ang pagkuwenta.